Impact
The flaw is an out‑of‑bounds write in the Codecs module of Google Chrome prior to version 150.0.7871.186. When a malicious HTML document is processed, the write corrupts internal memory structures, which can lead to a sandbox escape and allow the attacker to execute code outside the browser’s security boundaries. This weakness is classified as CWE‑787 and is considered high severity by Chromium’s security reviews.
Affected Systems
Users running any version of Google Chrome older than 150.0.7871.186 on supported platforms are affected. The vulnerability exists across all operating systems where the stable channel uses the affected codecs.
Risk and Exploitability
The CVSS score of 8.8 indicates a significant potential impact if the flaw is exploited, while the EPSS score of less than 1% shows a low probability of current exploitation. It is not listed in the CISA KEV catalog, suggesting no widespread active attacks. Exploitation would likely occur via a crafted HTML page accessed from a remote site or received through email, making the attack vector remote with user interaction. The overall risk is moderate due to the low exploitation probability, but the possible damage is high.
OpenCVE Enrichment
Debian DLA
Debian DSA